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DETAILED ACTION 

1 . This action is in response to correspondence received 28 February 2006. 

2. Claims 1-20 remain pending. 

Claim Rejections - 35 USC § 102 

3. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that 
form the basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(e) the invention was described in (1 ) an application for patent, published under section 122(b), by 
another filed in the United States before the invention by the applicant for patent or (2) a patent 
granted on an application for patent by another filed in the United States before the invention by the 
applicant for patent, except that an international application filed under the treaty defined in section 
351(a) shall have the effects for purposes of this subsection of an application filed in the United States 
only if the international application designated the United States and was published under Article 21(2) 
of such treaty in the English language. 

4. Claims 1-20 are rejected under 35 U.S.C. 102(e) as being anticipated by 
Yavatkar et al. (U.S. 6,735,702), hereinafter referred to as Yavatkar. 

5. Regarding claim 1 , Yavatkar discloses a method for reconstructing a path taken 
by undesirable network traffic through a computer network from a source of the traffic, 
the computer network including collectors located at fixed points within the network, the 
method comprising: 

collecting statistics at the collectors located at the fixed points from a plurality of 
measurement points located within routing and forwarding infrastructure of the computer 
network, the collectors interfacing with the forwarding infrastructure and taking samples 
of statistics from the infrastructure (col. 3, lines 25-29, Yavatkar discloses a method of 
using agents in order to collect data at a plurality of points within a network, the data 
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being information about the state of the network, col. 3, lines 49-54, stationary agents 
are used to collect statistics at selected points in the network.); and 

analyzing the samples of statistics to reconstmct the path taken by the 
undesirable network traffic through the network from the source of the traffic (col. 3, 
lines 29-32, Yavatkar discloses the method of determining the source and determining 
the path taken (reconstructing the path) based on the data gathered.). 

6. Claim 9 contains similar subject matter and is rejected under the same rationale 
as claim 1. . 

7. Regarding claim 2, Yavatkar discloses the method further comprising blocking 
undesirable network traffic within the computer network upstream of the points based on 
the reconstructed path (col. 14, lines 10-17, Yavatkar discloses methods used to 
combat attacks using source routing by quickly enabling the path of attack traffic to be 
found. When the path is found, appropriate action is taken, for example installing 
firewall entries at appropriate points in order to block attack traffic). 

8. Claim 10 contains similar subject matter and is rejected under the same rationale 
as claim 2. 

9. Regarding claim 3, Yavatkar discloses the method wherein the routing and 
forwarding infrastructure includes at least one router (Figure 3 and col. 7, II. 46-48, 
Yavatkar illustrates and discloses the use of routers.). 

10. Claim 1 1 contains similar subject matter and is rejected under the same rationale 
as claim 3. 
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1 1 . Regarding clainn 4, Yavatkar discloses the nnethod wherein the statistics include 
flow-based statistics which provide infornnation related to the same logical traffic flow 
(col. 14, II. 21-30, Yavatkar discloses monitoring at a plurality of nodes in order to 
determine the direction of traffic flow.). 

12. Claim 12 contains similar subject matter and is rejected under the same rationale 
as claim 4. 

13. Regarding claim 5, Yavatkar discloses the method wherein the statistics include 
packet statistics which provide information about a set of packets entering the routing 
and forwarding infrastructure (col. 15, II. 9-17, Yavatkar discloses methods used to 
monitor network traffic characteristics and detect attack traffic). 

14. Claim 13 contains similar subject matter and is rejected under the same rationale 
as claim 5. 

15. Regarding claim 6, Yavatkar discloses the method further comprising requesting 
and receiving upstream statistics from forwarding infrastructure of the computer network 
upstream the measurement points and wherein the step of analyzing includes the step 
of analyzing the upstream statistics to reconstruct the path taken by the undesirable 
network traffic (col. 14, II. 21-30, Yavatkar discloses monitoring at a plurality of nodes in 
order to determine the direction of traffic flow.). 

16. Claim 14 contains similar subject matter and is rejected under the same rationale 
as claim 6. 

17. Regarding claim 7, Yavatkar discloses the method wherein the step of analyzing 
includes the step of extracting profiles from the statistics collected at the plurality of 
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measurement points and comparing the profiles to reconstruct the path taken by the 
undesirable network traffic (col. 15, II. 9-17, Yavatkar discloses methods used to monitor 
network traffic characteristics and detect attack traffic). 

18. Claim 15 contains similar subject matter and is rejected under the same rationale 
as claim 7. 

1 9. Regarding claim 8, Yavatkar discloses the method wherein the computer network 
is the Internet (Figure 3 and col. 7, II. 43-44, Yavatkar illustrates and discloses the use 
of the Internet.). 

20. Claim 16 contains similar subject matter and is rejected under the same rationale 
as claim 8. 

21 . Regarding claim 1 7, Yavatkar discloses the method wherein the undesirable 
network traffic includes denial of service attacks (col. 13, II. 39-43, Yavatkar discloses 
the operation of the invention to be used to trace denial of service attacks.). 

22. Claim 19 contains similar subject matter and is rejected under the same rationale 
as claim 17. 

23. Regarding claim 18, Yavatkar discloses the method wherein the computer 
network includes a plurality of service provider networks (col. 13, 11. 44-48, Yavatkar 
discloses of Internet providers in order to assist in shutting down sources that are guilty 
of performing attacks on the network.). 

24. Claim 20 contains similar subject matter and is rejected under the same rationale , 
as claim 18. 
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Response to Arguments 

25. Applicant's arguments filed 28 February 2006 have been fully considered but 
they are not persuasive. Applicant argues in regards to independent claims 1 and 9 that 
Yavatkar fails to teach, disclose, or suggest "collecting statistics at collectors located at 
fixed points within a computer network from a plurality of measurement points located 
within routing and forwarding infrastructure of the computer network, the collectors 
interfacing with the forwarding infrastructure and taking samples of statistics from the 
forwarding infrastructure." The Examiner respectfully disagrees. Yavatkar discloses the 
utilization of agents to collect data on a network (col. 3, lines 26-29), the agents being of 
a type which are stationary agents (watchdog agent, col. 3, lines 49-54) that are 
positioned at certain points within the network. This method of assigning agents to 
certain locations is deemed equivalent to the claimed method of assigning collectors to 
fixed points within a computer network. Yavatkar's agents collect statistics at these 
certain locations (col. 3, lines 29-32). The agents being able to collect statistics at 
certain locations is deemed equivalent to applicant's claimed sample statistic collection 
method as found in independent claims 1 and 9. Therefore, it is determined that claims 
1 and 9 as written are not deemed patentable over Yavatkar. 



Application/Control Number: 09/855.810 
Art Unit: 2142 



Page 7 



Conclusion 



26. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time 
policy as set forth in 37 CFR 1 .1 36(a). 

A shortened statutory period for reply to this final action is set to expire THREE 
MONTHS from the mailing date of this action. In the event a first reply is filed within 
TWO MONTHS of the mailing date of this final action and the advisory action is not 
mailed until after the end of the THREE-MONTH shortened statutory period, then the 
shortened statutory period will expire on the date the advisory action is mailed, and any 
extension fee pursuant to 37 CFR 1 .136(a) will be calculated from the mailing date of 
the advisory action. In no event, however, will the statutory period for reply expire later 
than SIX MONTHS from the mailing date of this final action. 

Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Benjamin A. Ailes whose telephone number is (571)272- 
3899. The examiner can normally be reached on M-F 6:30-4, IFP Work Schedule. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Andrew Caldwell can be reached on (571)272-3868. The fax phone number 
for the organization where this application or proceeding is assigned is 571-273-8300. 




A5^LUi^E:W CALDWELL 
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Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). 
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